
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32432 is a Missing Authorization vulnerability in the WP Time Slots Booking Form WordPress plugin by CodePeople, classified under CWE-862. It allows unauthenticated network attackers to exploit incorrectly configured access control security levels to modify booking data. The vulnerability affects all versions of the plugin up to and including 1.2.42. It was published on March 13, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The root cause is a Missing Authorization flaw (CWE-862), where certain plugin endpoints or actions fail to verify whether the requesting user has appropriate permissions before processing the request. This falls under the broader category of Broken Access Control, where incorrectly configured security levels allow unauthenticated users to invoke privileged functionality. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity — meaning any remote attacker can trigger the vulnerable code path without preconditions. The vulnerability was reported and coordinated through Patchstack (Patchstack, Feedly).
Successful exploitation allows an unauthenticated attacker to modify booking data on affected WordPress installations, compromising data integrity. There is no direct confidentiality or availability impact per the CVSS scoring (C:N, A:N), but tampered booking records could disrupt business operations, cause scheduling conflicts, or enable fraudulent reservations. The scope is limited to the affected WordPress site's booking functionality and does not directly facilitate lateral movement or privilege escalation (Feedly).
The vulnerability has a low EPSS score of approximately 0.017%, indicating a low current probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, or threat actor attribution has been reported at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the zero-authentication requirement and network accessibility make it relatively straightforward to exploit if a PoC were to emerge (Feedly).
/wp-content/plugins/wp-time-slots-booking-form/).check_user_logged_in, current_user_can() calls absent from handlers).wp-admin/admin-ajax.php?action=<vulnerable_action>) with crafted parameters to modify booking records.wp-admin/admin-ajax.php with action parameters associated with the WP Time Slots Booking Form plugin from unknown or suspicious IP addresses.wp_* tables related to the plugin); no direct file system artifacts expected for this vulnerability type.Plugin users should update the WP Time Slots Booking Form plugin to a version above 1.2.42 as soon as a patched release is made available by CodePeople. In the interim, site administrators can restrict access to wp-admin/admin-ajax.php for unauthenticated users via web application firewall (WAF) rules or by using a security plugin such as Wordfence or Patchstack to virtually patch the vulnerability. Disabling the plugin entirely until a fix is available is also a viable option for high-risk environments (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."